Reminds me of the infamous "SSL added and removed here! :^)".
Does anyone know if there are any additional protections from snooping on their internal network?
edit: phrasing
Reminds me of the infamous "SSL added and removed here! :^)".
Does anyone know if there are any additional protections from snooping on their internal network?
edit: phrasing
> We use TLS 1.2 and a PFS cipher suite at both our origin data centers and proxies. Additionally, we’ve enabled upstream certificate validation and certificate pinning on our proxy servers. This helps ensure that the edge proxy server knows it’s talking to our upstream server, and not someone attempting a man-in-the-middle attack.
(N.B.: I work on security at Dropbox, and consulted on this design)
[1]: https://blogs.dropbox.com/tech/2016/11/infrastructure-update...
> Between July and December 2016, Dropbox did not comply with any non-US government legal process unless issued by a US court as a result of the Mutual Legal Assistance Treaty process.
... if that helps answer what you're getting at :)
I have to admit, part of the reason I use Dropbox is that I know I can get answers directly from employees on HN.
In this post they say specifically it is about the handshake:
https://blogs.dropbox.com/tech/2017/06/evolution-of-dropboxs...
I don't know if they use SSL/TLS to their upstreams, I'm just saying terminating in at the edge doesn't mean that is the end of all SSL/TLS. It is totally normal to terminate SSL/TLS at the edge, pretty much anyone using an HTTPS load balancer or CDN does it, but the LB or CDN can still use SSL/TLS to the upstreams and verify certificates of upstreams.